CVE Feed

    Dashboard / CVE / CVE-2017-15043

    CVE-2017-15043

    A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.5 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9 could allow an authenticated remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. This vulnerability is due to insufficient input validation on user-controlled input in an HTTP request to the targeted device. An attacker in possession of router login credentials could exploit this vulnerability by sending a crafted HTTP request to an affected system.

    Published:May 4, 2018
    Last Modified:Nov 21, 2024
    EPS:May 4, 2018
    EPSS Score:0.00018
    CVSS Score:8.8

    Affected Products

    Vendor
    Sierrawireless
    Product
    Es440
    Vendor
    Sierrawireless
    Product
    Es440 Firmware
    Vendor
    Sierrawireless
    Product
    Es450
    Vendor
    Sierrawireless
    Product
    Es450 Firmware
    Vendor
    Sierrawireless
    Product
    Gx400
    Vendor
    Sierrawireless
    Product
    Gx400 Firmware
    Vendor
    Sierrawireless
    Product
    Gx440
    Vendor
    Sierrawireless
    Product
    Gx440 Firmware
    Vendor
    Sierrawireless
    Product
    Gx450
    Vendor
    Sierrawireless
    Product
    Gx450 Firmware
    Vendor
    Sierrawireless
    Product
    Ls300
    Vendor
    Sierrawireless
    Product
    Ls300 Firmware
    Vendor
    Sierrawireless
    Product
    Mp70
    Vendor
    Sierrawireless
    Product
    Mp70 Firmware
    Vendor
    Sierrawireless
    Product
    Mp70e
    Vendor
    Sierrawireless
    Product
    Mp70e Firmware
    Vendor
    Sierrawireless
    Product
    Rv50
    Vendor
    Sierrawireless
    Product
    Rv50 Firmware
    Vendor
    Sierrawireless
    Product
    Rv50x
    Vendor
    Sierrawireless
    Product
    Rv50x Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High